Managing Staff Access
Practice administrators manage staff portal accounts at Admin > Portal Access. Each row is one staff account, with that person's permissions, sending identity, security status, and account actions.
Inviting a staff member
Click Invite user…, enter their email address, and choose a role:
- Administrator — full access to every portal feature, including this page.
- Practice user — access to the features you grant below.
The person receives an invitation email with a link to set their own password (see Signing In for the password and second-factor rules). Until they finish, their row shows invite pending and you can resend the invitation.
Feature grants
For practice users, checkboxes control access to the clinic features on the web: viewing and editing the schedule, plans, quotes, viewing and editing charts, transactions, and point-of-sale. Administrators always have every feature.
The Clinic Username column links a web account to the same person's InSched login, so shared role- and privilege-based security can apply on both. Practices using role-based access manage what each role may do on the Roles & Privileges page — the same roles InSched uses — instead of per-user checkboxes.
Sends Email As
Each staff member can be given their own sending identity for
inbox email replies: a mailbox on the practice's domain (for example
amber for amber@example.com) and a display name. Leave blank to use the practice's
default sending address. The mailbox must be a real address on your domain so patient
replies are delivered — see Practice Email.
Remote access
The Remote access checkbox controls whether that person may sign in from outside the practice's registered office networks (a second factor is then required — see Signing In). As a safeguard, the last administrator with remote access cannot have it switched off.
Account actions
The actions menu on each row provides:
- Resend invitation (unverified accounts) or Send password reset (active accounts).
- Unlock — clears a lockout after repeated failed sign-ins.
- Reset second factor — removes the person's authenticator app, passkeys, and recovery codes so they can enroll again (for a lost phone, for example). Requires confirmation; you cannot reset your own from this page.
- Deactivate / Reactivate — a deactivated account cannot sign in and its access tokens are revoked immediately, while all history is kept. The last active administrator cannot be deactivated, and you cannot deactivate yourself.
Every one of these actions is recorded in the practice's audit trail.